{"id":602,"date":"2026-08-11T11:56:17","date_gmt":"2026-08-11T11:56:17","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=602"},"modified":"2026-08-11T11:56:17","modified_gmt":"2026-08-11T11:56:17","slug":"penetration-testing","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/","title":{"rendered":"Penetration Testing: Types, Process and Reports"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: PENETRATION TESTING\n     Same design system as the VAPT and MFA glossary pages.\n     Paste the whole block into one Custom HTML block. No H1 (WP adds it).\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">A penetration test is an authorised, simulated attack on a system, carried out by a security professional to determine which weaknesses can genuinely be exploited and what an attacker would reach as a result.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Testing &amp; scanning<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>A penetration test answers a question automated tools cannot: not which vulnerabilities exist, but which ones an attacker can chain together to reach something valuable. A tester works under an agreed scope and written authorisation, exploits what they find, and documents each finding with evidence and reproduction steps. The deliverable is a report a customer or auditor will accept.<\/p>\n<\/div>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#compare\">How it differs from other testing<\/a><\/li>\n    <li><a href=\"#types\">Types of penetration test<\/a><\/li>\n    <li><a href=\"#process\">How a test is executed<\/a><\/li>\n    <li><a href=\"#report\">What the report should contain<\/a><\/li>\n    <li><a href=\"#compliance\">Where frameworks require it<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs penetration testing<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"compare\">How it differs from other testing<\/h2>\n\n<p>Four activities get confused during procurement. They differ on two axes: how much of the estate is covered, and how closely the exercise resembles a real attacker.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 380\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Positioning of vulnerability scanning, bug bounty, penetration testing and red team exercises by coverage and adversary realism.\">\n  <rect x=\"96\" y=\"40\" width=\"600\" height=\"266\" rx=\"16\" fill=\"#f4f5fd\"\/>\n  <line x1=\"396\" y1=\"40\" x2=\"396\" y2=\"306\" stroke=\"#dfe3f5\" stroke-width=\"1.5\"\/>\n  <line x1=\"96\" y1=\"173\" x2=\"696\" y2=\"173\" stroke=\"#dfe3f5\" stroke-width=\"1.5\"\/>\n\n  <text x=\"396\" y=\"26\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">HOW EACH APPROACH IS POSITIONED<\/text>\n\n  <text x=\"396\" y=\"332\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"600\" fill=\"#0f1538\">Coverage of the estate<\/text>\n  <text x=\"112\" y=\"332\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Narrow<\/text>\n  <text x=\"680\" y=\"332\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Broad<\/text>\n\n  <text x=\"70\" y=\"178\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"600\" fill=\"#0f1538\" transform=\"rotate(-90 70 178)\">Adversary realism<\/text>\n  <text x=\"88\" y=\"58\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">High<\/text>\n  <text x=\"88\" y=\"300\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Low<\/text>\n\n  <circle cx=\"196\" cy=\"88\" r=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"220\" y=\"86\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#1c267a\">Red team exercise<\/text>\n  <text x=\"220\" y=\"105\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">One objective, no warning, full realism<\/text>\n\n  <circle cx=\"386\" cy=\"150\" r=\"13\" fill=\"#4a52a8\"\/>\n  <text x=\"410\" y=\"148\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#4a52a8\">Penetration test<\/text>\n  <text x=\"410\" y=\"167\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Defined scope, exploited and evidenced<\/text>\n\n  <circle cx=\"586\" cy=\"212\" r=\"13\" fill=\"#2f6a89\"\/>\n  <text x=\"308\" y=\"216\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#2f6a89\">Bug bounty programme<\/text>\n  <text x=\"308\" y=\"235\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Continuous, unpredictable coverage<\/text>\n  <line x1=\"316\" y1=\"212\" x2=\"568\" y2=\"212\" stroke=\"#bfd9e9\" stroke-width=\"1.5\" stroke-dasharray=\"4 4\"\/>\n\n  <circle cx=\"616\" cy=\"272\" r=\"13\" fill=\"#8a90a8\"\/>\n  <text x=\"332\" y=\"276\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#0f1538\">Vulnerability scanning<\/text>\n  <text x=\"332\" y=\"295\" text-anchor=\"end\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Every asset, known issues only<\/text>\n  <line x1=\"342\" y1=\"272\" x2=\"598\" y2=\"272\" stroke=\"#dfe3f5\" stroke-width=\"1.5\" stroke-dasharray=\"4 4\"\/>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Scanning covers the most ground and proves the least. A red team proves the most and covers a single objective.<\/figcaption>\n<\/figure>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Approach<\/th><th>What it produces<\/th><th>Best used when<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong><a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">Vulnerability scanning<\/a><\/strong><\/td><td>Known issues across every asset, with false positives<\/td><td>Continuously, between tests<\/td><\/tr>\n    <tr><td><strong>Penetration test<\/strong><\/td><td>Exploited findings with evidence, ranked by impact<\/td><td>A customer or auditor wants assurance<\/td><\/tr>\n    <tr><td><strong>Red team exercise<\/strong><\/td><td>Proof that detection and response work<\/td><td>A security team already exists<\/td><\/tr>\n    <tr><td><strong>Bug bounty<\/strong><\/td><td>Findings from external researchers, paid per issue<\/td><td>Mature product with a triage process<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">A note on sequence<\/p>\n  <p>Red team exercises and bug bounty programmes assume someone is available to respond to findings. For a team without a dedicated security hire, a scoped penetration test with a retest delivers considerably more value for the same budget.<\/p>\n<\/div>\n\n<h2 id=\"types\" class=\"c-sage\">Types of penetration test<\/h2>\n\n<p>The type follows what is being attacked. Most startups begin with the first two and add others as the product grows.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Type<\/th><th>What is tested<\/th><th>Typical trigger<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Web application<\/strong><\/td><td>Auth, session handling, tenant isolation, injection<\/td><td>First enterprise customer or audit<\/td><\/tr>\n    <tr><td><strong>API<\/strong><\/td><td>Object level authorisation, rate limits, shadow endpoints<\/td><td>Any public or partner API<\/td><\/tr>\n    <tr><td><strong>Mobile application<\/strong><\/td><td>Local storage, cert pinning, secrets in the binary<\/td><td>A mobile client ships<\/td><\/tr>\n    <tr><td><strong>External network<\/strong><\/td><td>Internet-facing services, ports, remote access, TLS<\/td><td>Self-managed infrastructure<\/td><\/tr>\n    <tr><td><strong>Internal network<\/strong><\/td><td>Lateral movement, privilege escalation, segmentation<\/td><td>Regulated or enterprise buyers<\/td><\/tr>\n    <tr><td><strong>Cloud configuration<\/strong><\/td><td>IAM roles, storage permissions, security groups, logging<\/td><td>Multiple cloud accounts<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"process\" class=\"c-apri\">How a test is executed<\/h2>\n\n<p>Testers work to a published methodology rather than improvising: the OWASP Web Security Testing Guide for application work, NIST SP 800-115 and the Penetration Testing Execution Standard for the wider process. Ask which one a provider follows.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 250\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Penetration test execution: reconnaissance, scanning, exploitation, post-exploitation, reporting, then retest after remediation.\">\n  <defs>\n    <marker id=\"pt1\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker>\n    <marker id=\"pt2\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker>\n  <\/defs>\n\n  <text x=\"380\" y=\"26\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">EXECUTION PHASES<\/text>\n\n  <rect x=\"12\" y=\"52\" width=\"130\" height=\"66\" rx=\"12\" fill=\"#e9ecfa\"\/>\n  <text x=\"77\" y=\"80\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#4a52a8\">Reconnaissance<\/text>\n  <text x=\"77\" y=\"100\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Map the real surface<\/text>\n  <line x1=\"146\" y1=\"85\" x2=\"164\" y2=\"85\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#pt1)\"\/>\n\n  <rect x=\"172\" y=\"52\" width=\"130\" height=\"66\" rx=\"12\" fill=\"#dfe3f5\"\/>\n  <text x=\"237\" y=\"80\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3d4590\">Scanning<\/text>\n  <text x=\"237\" y=\"100\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Enumerate candidates<\/text>\n  <line x1=\"306\" y1=\"85\" x2=\"324\" y2=\"85\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#pt1)\"\/>\n\n  <rect x=\"332\" y=\"52\" width=\"130\" height=\"66\" rx=\"12\" fill=\"#c2d9ec\"\/>\n  <text x=\"397\" y=\"80\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#25547a\">Exploitation<\/text>\n  <text x=\"397\" y=\"100\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Prove what is real<\/text>\n  <line x1=\"466\" y1=\"85\" x2=\"484\" y2=\"85\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#pt1)\"\/>\n\n  <rect x=\"492\" y=\"52\" width=\"130\" height=\"66\" rx=\"12\" fill=\"#7b9dc9\"\/>\n  <text x=\"557\" y=\"80\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">Post-exploitation<\/text>\n  <text x=\"557\" y=\"100\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#eaf1f8\">Establish the impact<\/text>\n  <line x1=\"626\" y1=\"85\" x2=\"644\" y2=\"85\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#pt1)\"\/>\n\n  <rect x=\"652\" y=\"52\" width=\"96\" height=\"66\" rx=\"12\" fill=\"#1c267a\"\/>\n  <text x=\"700\" y=\"80\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">Reporting<\/text>\n  <text x=\"700\" y=\"100\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Evidence and<\/text>\n  <text x=\"700\" y=\"114\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">remediation<\/text>\n\n  <path d=\"M700,124 L700,176 L397,176\" fill=\"none\" stroke=\"#4a52a8\" stroke-width=\"2\" stroke-dasharray=\"6 5\" marker-end=\"url(#pt2)\"\/>\n  <rect x=\"286\" y=\"186\" width=\"222\" height=\"44\" rx=\"12\" fill=\"#ffffff\" stroke=\"#4a52a8\" stroke-width=\"2\"\/>\n  <text x=\"397\" y=\"213\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#1c267a\">Retest after remediation<\/text>\n  <text x=\"530\" y=\"170\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">You fix, the tester verifies<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>The retest is the phase most often excluded from a quotation, and the one that produces the evidence buyers ask for.<\/figcaption>\n<\/figure>\n\n<h2 id=\"report\" class=\"c-plum\">What the report should contain<\/h2>\n\n<p>The report is the product. Request a redacted sample before signing, and check it against these six.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Executive summary<\/p>\n    <p>Overall risk position, written for a reader without a technical background.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Scope and method<\/p>\n    <p>Assets in scope, methodology followed, and the exact dates of testing.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Evidence per finding<\/p>\n    <p>Severity, affected endpoint, and proof that the issue was exploited.<\/p>\n  <\/div>\n  <div class=\"tcard a\">\n    <p class=\"n\">Reproduction steps<\/p>\n    <p>Detailed enough for an engineer to reproduce the finding independently.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Named remediation<\/p>\n    <p>Specific corrective actions rather than general advice to apply patches.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Retest results<\/p>\n    <p>Which findings were closed, and on what date they were verified.<\/p>\n  <\/div>\n<\/div>\n\n<div class=\"callout\">\n  <p class=\"k\">Before you sign<\/p>\n  <p>Confirm three things: that the retest is included rather than billed separately, that testers hold recognised credentials such as OSCP or CREST, and that an attestation letter is provided for sharing with customers who should not receive the full report.<\/p>\n<\/div>\n\n<h2 id=\"compliance\" class=\"c-sky\">Where frameworks require it<\/h2>\n\n<table class=\"h-plum\">\n  <thead>\n    <tr><th>Framework<\/th><th>Status<\/th><th>Where it appears<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr>\n      <td><strong>PCI DSS v4.0<\/strong><\/td>\n      <td><span class=\"pill p-req\">Required<\/span><\/td>\n      <td>Requirement 11.3: internal and external penetration testing at least annually and after significant change.<\/td>\n    <\/tr>\n    <tr>\n      <td><strong><a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a>:2022<\/strong><\/td>\n      <td><span class=\"pill p-exp\">Expected<\/span><\/td>\n      <td><a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A<\/a> 8.8 (technical vulnerabilities) and A 8.29 (security testing in development and acceptance).<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>SOC 2<\/strong><\/td>\n      <td><span class=\"pill p-exp\">Expected<\/span><\/td>\n      <td>Not named in the <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-controls-cc1-cc9\/\">Trust Services Criteria<\/a>. Auditors accept a test report and <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-evidence-collection\/\">retest as evidence<\/a> under CC4.1 and CC7.1.<\/td>\n    <\/tr>\n    <tr>\n      <td><strong>Buyer questionnaires<\/strong><\/td>\n      <td><span class=\"pill p-ask\">Asked<\/span><\/td>\n      <td>The date of the most recent test, who performed it, and whether findings were remediated.<\/td>\n    <\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto runs penetration testing<\/h2>\n\n<p>Osto provides expert-led penetration testing inside the platform rather than as a separate consulting engagement. Findings are rated by severity with affected endpoints identified, and remediation and retest reports are produced in the same system.<\/p>\n\n<p>Because that platform also runs the WAF, CSPM, code security and compliance modules, test evidence already sits where auditors draw from. That is why testing fits inside Osto&#8217;s 7-day SOC 2 readiness phase.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Test what an attacker would reach first<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Expert-led penetration testing with remediation and retest reports, alongside continuous scanning across your applications, APIs and cloud.<\/p>\n  <a href=\"https:\/\/www.osto.one\/contact\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:'Inter',-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/www.osto.one\/book-demo\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Retest included &middot; Reports auditors accept &middot; One platform, everything<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is a penetration test?<\/summary>\n  <p>A penetration test is an authorised simulated attack on a system, performed by a security professional to identify which weaknesses can be exploited and what an attacker would be able to reach. It produces a report of validated findings with evidence, reproduction steps and remediation guidance.<\/p>\n<\/details>\n\n<details>\n  <summary>How is a penetration test different from a vulnerability scan?<\/summary>\n  <p>A vulnerability scan is automated and reports known issues across every asset, including false positives. A penetration test is performed manually, confirms which issues are genuinely exploitable, and identifies flaws in business logic that scanners cannot detect.<\/p>\n<\/details>\n\n<details>\n  <summary>How long does a penetration test take?<\/summary>\n  <p>A single web application generally requires a few days to two weeks including reporting. Larger scopes covering applications, APIs and internal networks can run several weeks. Scheduling with a provider typically adds further lead time.<\/p>\n<\/details>\n\n<details>\n  <summary>How often should a penetration test be performed?<\/summary>\n  <p>At least annually, and after any significant change such as a new payment flow, a new authentication provider or a cloud migration. PCI DSS makes the annual test mandatory; other frameworks treat it as expected practice.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between a penetration test and a red team exercise?<\/summary>\n  <p>A penetration test examines a defined scope for exploitable weaknesses and documents them. A red team exercise pursues a single objective without warning the defending team, and measures whether detection and response function correctly. Red teaming is appropriate once a security function is already in place.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">VAPT<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-assessment\/\">Vulnerability Assessment<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/\">Vulnerability Scanning<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; Red Teaming &middot; DAST<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>A penetration test is an authorised, simulated attack on a system, carried out by a security professional to determine which\u2026<\/p>\n","protected":false},"author":8,"featured_media":601,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[],"class_list":["post-602","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/602","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=602"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/602\/revisions"}],"predecessor-version":[{"id":603,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/602\/revisions\/603"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=602"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=602"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=602"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}